Home

Jun 8, 2018

Botnet That Previously Hacked Over 500,000 Routers Has Come Back Stronger


According to Telemetry data gathered this week, the VPN filter botnet is trying to make a comeback said security researchers. JASK and HreyNoise Intelligence revealed this matter on Friday which showed the same threat actor was built into the second iteration of the VPN filter which is attempting to compromise new routers and build a new VPNFilter.

Category:IT 
Posted by: Admin

According to Telemetry data gathered this week, the VPN filter botnet is trying to make a comeback said security researchers. JASK and HreyNoise Intelligence revealed this matter on Friday which showed the same threat actor was built into the second iteration of the VPN filter which is attempting to compromise new routers and build a new VPNFilter.

Most of the scans have looked for Mikrotik routers with port 2000 exposed to the network which are in Ukrainian locations. Furthermore, the old VPNFilter also consisted of C&C server which is dedicated to managing Ukrainian devices which are entirely separate from the initial botnet.

The public disclosure revealed that the group behind the updated version is APT28 which is a Russian cyber-espionage unit and was currently preparing to attack Ukraine’s IT infrastructure. The researchers of Cisco Talos revealed that this botnet’s existence and also notified the FBI which helped them take over the domain which is currently managed to use the VPN filter command and control infrastructure. This didn’t stop the group from starting a new attack and finding new devices to compromise on the network. The malware is considered as one of the most advanced pieces of IoT malware which compromises the system in a three-stage attack.

The first stage consists of a payload that can achieve boot persistence on devices which can also survive the reboot from routers. The second stage follows by the injection of a Remote Access Token (RAT) and for the third stage, the hackers use this RAT software to add malicious functionality to the router.

A report from Estonian Foreign Intelligence Service claimed that APT28 is a unit of Russian Military Main Intelligence Directorate (GRU) which is behind many cyber attacks on the past such as NotPetya ransomware and BlackEnergy attacks. The Ukrainian officials need to strong to survive the attack from the malware again as it has risen from the ashes.

Take your time to comment on this article.

authorarticle: Master3395

image: 

sources: latesthackingnews.com

keywords: attack, Ukrainian Routers, VPN Filter

Previous Article
Next Article
Discord

Page 1 of 336  >  >>

Now the October update for Windows 10 rolls out

windows10.jpg

Nov 21, 2018 | Category: Microsoft | Comments

Finally - here are the improvements.

Microsoft has had a very hard time rolling out the October update to Windows 10 (version 1809), but now it seems that the pieces fall into place.

read more…

Female is reported to have reset her iPhone under investigation

police-iphone.jpeg

Nov 20, 2018 | Category: Apple | Comments

The phone was used for evidence purposes in a shooting event.

Often information that can be retrieved from phones relevant to the police is being investigated in a criminal case. Such important information can be a lot of things, including an overview of contacts and possible planning of crime - largely the most likely to help criminalize a person.

read more…

CloudFlare's privacy app is here

cloudflare-1.1.1.1-ios-android.png

Nov 19, 2018 | Category: IT | Comments

Free and available now for iOS and Android.

It's been several months since the networking giant Cloudflare showed the DNS service 1.1.1.1 that focuses on privacy, readily available to consumers. Now the application is available for free for Apple devices and Android.

read more…

Page 1 of 336  >  >>